Court Rules

Privacy Enforcement Tracker

1,506 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,506

Total Actions

16

Jurisdictions

$26.6B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
COEnforcement Action

Home Defense Solutions

Colorado contractor Rocco Roberts was criminally charged for defrauding a Boulder family during an asbestos remediation project. He allegedly misrepresented his licensing, performed the abatement improperly, exposed the home to asbestos, and provided a fraudulent clearance test. Roberts collected $8,400 for the work and faces felony charges including hazardous substance incident, forgery, and theft.

LowSecurity Failure
FTCSettlement

Elite Events and Tickets LLC

The FTC alleged that Elite Events and Tickets LLC, doing business as Smart Scalpers, violated the Better Online Ticket Sales Act by circumventing security measures to bypass ticket purchase limits for over 2,400 events, reselling tickets at a profit. The proposed order requires payment of $300,000 (with a total penalty of $10.7 million partially suspended) and permanently prohibits the company and its owners from engaging in such circumvention tactics.

MediumSecurity Failure

$300K

NYGuidance

New York Attorney General's Office

New York Attorney General Letitia James submitted testimony to the Senate Committee on Homeland Security and Governmental Affairs' Permanent Subcommittee on Investigations, calling for stronger regulations on cryptocurrency platforms to protect consumers and investors from scams. The testimony details the flood of cryptocurrency scams costing Americans billions annually and criticizes the Digital Asset Market Clarity Act for undermining state enforcement efforts.

LowSecurity Failure
VASettlementMultistate

23andMe, Inc.

Virginia Attorney General Jay Jones joined a coalition of 42 state attorneys general in a multistate settlement with 23andMe over a 2023 data breach that exposed the genetic data of approximately 6.9 million customers. The settlement requires 23andMe to pay $18 million to the states and $46.75 million to affected consumers, resolving allegations of inadequate security practices and delayed breach notification.

CriticalData BreachSecurity FailureHealth Data

$18.0M

VASettlementMultistate

23andMe

Attorney General Jay Jones joined 42 attorneys general in a multistate settlement with 23andMe's bankruptcy trustee over a 2023 data breach that compromised genetic data of nearly 7 million customers. The settlement includes $150 million in allowed claims, with immediate recovery of $18 million from bankruptcy funds, of which Virginia receives $662,649. The settlement also requires enhanced data security measures and consumer protections for the new entity, 23andMe Research Institute.

MediumData BreachSecurity FailureHealth Data

$663K

TXSettlementMultistate

23andMe

Texas Attorney General Ken Paxton secured a $150 million multistate settlement against 23andMe following a 2023 data breach that exposed genetic and personal data of 6.9 million consumers. The settlement resolves bankruptcy claims and requires enhanced data security, risk assessments, and an independent advisory board, with immediate recovery of $18 million from bankruptcy funds.

CriticalData BreachSecurity FailureBreach Notification Delay

$150.0M

NYSettlementMultistate

23andMe

New York Attorney General Letitia James and a bipartisan coalition of 42 other attorneys general secured an $18 million settlement from genetic testing company 23andMe for failing to protect customers' private genetic data. The October 2023 data breach exposed sensitive genetic information of 6.9 million consumers, including 305,245 in New York, with some data published for sale on the dark web. The settlement includes monetary penalties and new data protection requirements for the company and its successor, 23andMe Research Institute.

CriticalData BreachSecurity FailureBreach Notification Delay

$18.0M

CTSettlementMultistate

23andMe

Attorney General William Tong led a coalition of 42 attorneys general in a settlement with the bankruptcy trustee for 23andMe, resolving allegations from a 2023 data breach that compromised the genetic data of 6.9 million customers. The settlement includes $150 million in allowed claims, with $18 million paid from bankruptcy funds, and requires enhanced data security measures for the new entity holding the data.

HighData BreachSecurity FailureHealth Data

$18.0M

ORSettlementMultistate

23andMe

A coalition of 42 state attorneys general settled bankruptcy claims against 23andMe following a 2023 data breach that compromised genetic data of 6.9 million customers. The settlement includes $150 million in allowed claims, with $18 million paid from bankruptcy funds, and requires enhanced data security measures for the successor entity, 23andMe Research Institute.

HighData BreachSecurity FailureHealth Data

$18.0M

NJSettlementMultistate

23andMe, Inc.

Attorney General Jennifer Davenport joined a bipartisan coalition of 42 attorneys general in announcing a settlement with the bankruptcy trustee for 23andMe, resolving allegations from a 2023 data breach that compromised genetic data of 6.9 million people worldwide, including nearly 150,000 in New Jersey. The settlement provides $18 million to states from available bankruptcy funds, plus enhanced data security and consumer deletion rights for the successor entity, 23andMe Research Institute.

CriticalData BreachSecurity FailureBreach Notification Delay

$18.0M

COSettlementMultistate

23andMe, Inc.

A coalition of 42 state attorneys general settled with the bankruptcy trustee for 23andMe over a 2023 data breach that exposed genetic data of 6.9 million customers. The states will receive $18 million from bankruptcy funds, and 23andMe agreed to enhanced data security requirements and consumer deletion rights as part of the asset sale to TTAM Research Institute.

HighData BreachSecurity FailureBiometric Data

$18.0M

MNSettlementMultistate

23andMe, Inc.

A coalition of 42 state attorneys general reached a settlement with the bankruptcy trustee for 23andMe over a 2023 data breach that compromised the genetic data of 6.9 million customers. The settlement provides $18 million from bankruptcy funds, with Minnesota receiving $514,871, and imposes data security requirements on the successor entity, 23andMe Research Institute.

HighData BreachSecurity FailureBreach Notification Delay

$18.0M

TXSettlementMultistate

Block, Inc.

Attorney General Ken Paxton secured a $45 million multistate settlement with Block, Inc. (Cash App) for misleading consumers about the safety of its platform and failing to protect users from fraud. The settlement requires Cash App to maintain 24-hour customer support, cease deceptive safety claims, and fulfill its legal duty to investigate and reimburse unauthorized transactions.

CriticalSecurity FailureNotice Failure

$45.0M

NYSettlementMultistate

Block, Inc.

New York Attorney General Letitia James and a bipartisan coalition of 45 other attorneys general secured $45 million from Block, Inc., the company behind Cash App, for misleading users about the platform's security and failing to protect them from fraud. The settlement requires Block to implement changes including maintaining live customer support, stopping misleading marketing, and fulfilling legal obligations to investigate fraud claims and reimburse users for unauthorized transactions.

CriticalSecurity FailureNotice FailureConsent Failure

$45.0M

CTSettlementMultistate

Block, Inc.

Attorney General Tong announced a $45 million multistate settlement with Block, Inc., the company behind Cash App, for misleading consumers about the safety of the platform, failing to protect users from fraud, and not providing promised fraud protection and resolution services. The settlement requires Block to implement major reforms including real customer support, transparent communications, and security commitments, and reaffirms Block's commitment to distribute between $75 million and $120 million to compensate consumers as part of a separate CFPB settlement.

HighSecurity FailureNotice FailureConsent Failure

$45.0M

NJSettlementMultistate

Block, Inc.

Block, Inc. agreed to a $45 million multistate settlement with 46 states for allegedly misleading consumers about the safety of Cash App, failing to protect users from fraud, and not providing promised fraud protection. The settlement requires Block to improve customer support, stop misleading claims, and educate consumers about fraud.

CriticalSecurity FailureNotice Failure

$45.0M

VASettlementMultistate

Block, Inc.

Block, Inc., the parent company of Cash App, agreed to a $45 million multistate settlement with 46 states for misleading consumers about the safety of Cash App and failing to protect users from fraud. The settlement requires Block to improve customer support, stop deceptive marketing, and fulfill legal obligations to investigate fraud and reimburse unauthorized transactions.

CriticalNotice FailureSecurity Failure

$45.0M

COSettlementMultistate

Block, Inc.

Attorney General Phil Weiser announced a $45 million multistate settlement with Block, Inc., the company behind Cash App, for misleading consumers about the safety of the platform and failing to protect users from fraud. The settlement requires Block to implement antifraud measures, provide customer support, and stop deceptive marketing practices.

HighSecurity FailureNotice FailureConsent Failure

$45.0M

MNSettlementMultistate

Block, Inc.

Attorney General Keith Ellison announced a $45 million multistate settlement with Block, Inc., the company behind Cash App. The settlement resolves allegations that Block misled consumers about the safety of Cash App, failed to protect users from fraud, and did not provide promised fraud protection and resolution. Block agreed to implement responsible practices including maintaining customer support, offering live support, stopping misleading claims, and fulfilling legal obligations to investigate fraud and reimburse users.

HighSecurity FailureNotice FailureConsent Failure

$45.0M

NJGuidance

New Jersey Bureau of Securities

The New Jersey Bureau of Securities announced its 2026 annual investment adviser examination, with a particular focus on firms' use of artificial intelligence and cybersecurity protocols. The examination requires nearly 800 registered investment adviser firms to answer questions about AI use in portfolio management, data protection policies, and third-party vendor due diligence. Failure to comply may result in administrative action.

LowSecurity FailureAI/Automated Decisions
FTCSettlement

Illuminate Education Inc.

The FTC finalized a consent order against Illuminate Education Inc. for failing to secure students' personal data, leading to a breach affecting 10.1 million students. The order requires Illuminate to implement a data security program, delete unnecessary data, and limit data collection, but imposes no monetary penalty.

LowSecurity FailureData BreachChildren's Data
TXInvestigation

Drone Nerds, LLC

Texas Attorney General Ken Paxton initiated an investigation into Drone Nerds, LLC over its partnership with CCP-affiliated Anzu Robotics, which markets drones with concealed surveillance capabilities and unauthorized data collection risks. Drone Nerds is accused of deceiving Texas consumers by misrepresenting Anzu’s ties to China and falsely claiming the drones are U.S.-based with secure privacy practices. The investigation is being conducted under the Texas Deceptive Trade Practices Act, with a Civil Investigative Demand issued to gather evidence of consumer deception and privacy violations.

LowSecurity FailureUnauthorized Data Sharing
OREnforcement ActionMultistate

U.S. Environmental Protection Agency(EPA)

Environmental enforcement action where Oregon Attorney General Dan Rayfield, along with a coalition of states and cities, filed a lawsuit challenging the EPA's unlawful rescission of the 2009 Endangerment Finding on greenhouse gas emissions. The challenge argues that the rescission ignores scientific evidence and legal precedent, threatening public health and environmental protections.

LowSecurity Failure
OREnforcement ActionMultistate

Department of Education

Privacy enforcement action where Oregon AG and a coalition of 16 other states sue the Trump Administration to stop the Department of Education's new IPEDS data reporting requirements, arguing they jeopardize student privacy, lack proper definitions, and risk data errors and identification.

LowUnauthorized Data SharingNotice FailureSecurity Failure
OREnforcement Action

Devon T. Horace(Alberta Main Street)

Consumer protection case involving theft of charitable funds. Former Alberta Main Street president Devon T. Horace pleaded no contest to theft and falsifying business records, paid $85,080.95 in restitution, and was sentenced to probation and community service.

LowSecurity Failure
HHSEnforcement Action

BMG of Kansas, Inc.

BMG of Kansas, Inc. (Health Plan, KS) reported a HIPAA breach affecting 1,327 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Manhattan Retirement Foundation d/b/a Meadowlark Hills

Manhattan Retirement Foundation d/b/a Meadowlark Hills (Healthcare Provider, KS) reported a HIPAA breach affecting 14,442 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

AltaMed Health Services Corporation

AltaMed Health Services Corporation (Healthcare Provider, CA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Couve Healthcare Consulting, LLC DBA Evergreen Healthcare Group

Couve Healthcare Consulting, LLC DBA Evergreen Healthcare Group (Business Associate, WA) reported a HIPAA breach affecting 11,795 individuals. Breach type: Hacking/IT Incident. Location of breached information: Electronic Medical Record.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

QualDerm Partners, LLC

QualDerm Partners, LLC (Healthcare Provider, TN) reported a HIPAA breach affecting 3,117,874 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

CriticalData BreachHealth DataSecurity Failure

Explore Enforcement Data